ZF-DDOS: An Enhanced Statistical-Based DDoS Detection Approach using Integrated Z-Score and Fast-Entropy Measures
Mahmoud Hassan, Khaked Metwally, Mohamed A. Elshafey · 2024
The fast emerging of Internet technologies and 5G connectivity played an imperative role in our daily lives. This allowed to incredible increase in the Internet usage, so, a large amount of information is exchanged between various connected devices daily. However, this development introduced a great cyber security challenge for all individuals and enterprises. Evolution of new and different types of network attacks grows quickly to compromise one or more of the Confidentiality, Integrity, and Availability (CIA) Triad principles that guarantee the security of information systems. Distributed Denial of Service (DDoS) attack is one of the most destructive attacks that targets the availability in the CIA Triad. Many research works have been proposed targeting DDoS attacks detection in recent networks. However, the detection accuracy still a challenging task. This paper presents an enhanced statistical-based DDoS detection approach that mainly relies on the integration of Z-Score and Fast-Entropy statistical measurements. Moreover, the proposed approach integrates additional statistical features that contribute significantly on higher DDoS detection accuracy over statistical based benchmarks. In experiments, the proposed approach has been tested on CIC-DDOS-2019 dataset and resulted markable improvements in DDOS detection accuracy of 25% and 10% over Fast-Entropy- and Z-Score statistical-based benchmarks, respectively.